What a firewall actually does when it "blocks" something
The one-sentence version
A firewall is a set of rules, checked in order, that decides — for every single packet trying to cross a boundary — whether to let it through, drop it silently, or reject it with an error, based on things like source and destination address, port number, and connection state.
What "blocking" actually looks like mechanically
Two very different behaviors both get called "blocking." DROP silently discards the packet — the sender gets no response at all and just times out, with no idea why. REJECT refuses the packet with an explicit response, so the sender knows immediately. Most production firewalls default to DROP for anything coming from outside precisely because it gives a port-scanning attacker zero information back: a REJECT tells them "something is here, just closed," while a DROP looks identical to "nothing is here at all."
Rules are read in order, and order changes the outcome
Picture two rules: rule 1 allows port 22 from your office IP, rule 2 denies everything from everywhere. Most firewalls apply the first rule that matches and stop there. Swap the order — deny-everything first, allow-22 second — and port 22 never even gets evaluated, because the broad deny already caught the packet. The exact same two rules, in a different order, produce a completely different, and often accidental, security posture.
Stateful vs. stateless — the part most explanations skip
A modern firewall doesn't evaluate every packet from scratch. Once it lets an outbound connection through, it remembers that connection in a state table, and automatically allows the return traffic for it without needing a separate matching inbound rule. That's why you can browse the web without a rule saying "allow inbound port 443 responses" — the state table handles it silently. It's also exactly why a firewall alone doesn't stop everything: once a connection is allowed, the firewall isn't inspecting what flows back over it.
What people get wrong
"A firewall protects me from viruses" — no. A firewall controls which connections are allowed to happen at all; it has no idea what's inside the data a permitted connection carries. Malware downloaded over an allowed HTTPS connection sails straight through, because the firewall's job ends at "is this connection allowed," not "is this content safe."
One caveat worth knowing
There's a real difference between a host-based firewall (running on your own machine, controlling what that one device sends and receives) and a network firewall (sitting at the edge of a whole network, controlling what crosses its boundary). Most real setups use both, layered — a firewall is one layer of a security posture, never a complete strategy by itself.